Adobe has released updated versions of their Experience Manager. Updates fix a bunch of vulnerabilities of which some are categorized as critical. Successful exploitation of these vulnerabilities could result in arbitrary JavaScript execution in the browser.
Affected versions
Adobe Experience Manager
- 6.5.5.0 and earlier
- 6.4.8.1 and earlier
- 6.3.3.8 and earlier
- 6.2 SP1-CFP20 and earlier
AEM Forms add-on
- AEM Forms Service Pack 5 add-on package for AEM 6.5.5.0
- AEM Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 1 (6.4.8.1)
More information from the Adobe's security advisory.
Saturday, September 12, 2020
Adobe Experience Manager Updated
Adobe Framemaker Updated
Adobe has released an updated version of their Framemaker. New version contains fixes to two critical security vulnerabilities (CVE-2020-9726, CVE-2020-9725). Successful exploitation of the vulnerabilities could lead to arbitrary code execution in the context of the current user.
Affected are versions 2019.0.6 and below for Windows.
More information from the Adobe's security advisory.
Adobe InDesign Update Available
Adobe have released updated version of Adobe InDesign. The new update resolves critical vulnerabilities that could be abused to execute code remotely in the context of the current user.
Affected versions:
- Adobe InDesign earlier than 15.1.2
More information can be read from Adobe's security bulletin.
Microsoft Security Updates For September 2020
Microsoft have released security updates for September 2020.
Summary of the updates (filter by inserting 08/12/2020 to the From field and 09/08/2020 to the To field) here.
Saturday, September 5, 2020
Latest PHP Versions Available
PHP development team has released 7.4.10 and 7.3.22 versions of the PHP scripting language. New versions contain bug fixes. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.
Changelogs:
Version 7.4.10
Version 7.3.22
Foxit PhantomPDF Update Available
Foxit Software has released version 9.7.3 of their Foxit PhantomPDF software. The new version contains fixes for security vulnerabilities that if exploited may allow an attacker to execute arbitrary code in target system.
Affected versions:
Foxit PhantomPDF 9.7.2.29539 and earlier (Windows)
More information can be read here.
Foxit Studio Photo Updated
Foxit has released a new version of their Studio Photo application. Among other fixes the updated version patches an information disclosure vulnerability. An attacker can leverage this vulnerability to execute code in the context of the current process. (CVE-2020-17403/CVE-2020-17404)
Affected versions:
3.6.6.927 and earlier
More information can be read here. The latest version is downloadable here.